Security Observatory by Fortmilo

See what can reach your Salesforce org — and keep the evidence needed to review it.

Security Observatory turns observed application, OAuth, credential and endpoint evidence into durable records with ownership, purpose and review context — and keeps the evidence behind each one.

Currently in sandbox validation. Not yet available for public installation.

  • Free
  • Read-only and advisory
  • Single org
  • Evidence retained in your Salesforce org

Prefer email? info@fortmilo.co.uk

Fortmilo

Turn observed evidence into accountable application records

Supported observed applications and integrations can become durable governed records that remain useful across rescans.

Where supported, a record can hold a business owner, technical owner, vendor, purpose, business context, review status, last-reviewed date and relevant renewal or review context. Human-entered governance context is preserved while source provenance, linked OAuth context and associated findings keep the record traceable; fields are completed through review rather than assumed from the source.

The independent Security Benchmark for Salesforce (SBS) calls for authoritative inventories, documented ownership, justification and review evidence across key Salesforce security areas; Security Observatory provides a governed place for that context alongside the technical evidence.

Security Observatory governance context for a Salesforce connected application, showing owners, vendor, purpose and review status.
Governed application context in Security Observatory, linking ownership, purpose and review information to retained technical evidence.

Review the credentials, endpoints and public surfaces that connect your org

Security Observatory reviews supported integration configuration without claiming to discover every integration.

Credentials and outbound endpoints

Review Named Credentials, External Credentials and outbound endpoints with relevant retained configuration and security findings.

Endpoint and egress configuration

Bring Remote Site Settings, CSP Trusted Sites and the CORS allowlist into the same bounded review, with certificates available as supporting evidence where relevant.

Public Salesforce surfaces

Review supported Salesforce Sites and Experience Cloud evidence alongside the applications and connections that give it context.

See OAuth access in the context of the user and the application

Correlate retained OAuth authorisation evidence with the observed application, supported user state, stale or non-use evidence when available, governed application context and associated findings. Inactive or frozen user context remains explicit where the source supports it.

An authorisation record does not prove a credential currently works, and Security Observatory never probes it.

Sensitive evidence boundary

No tokens · No session IDs · No secrets · No certificate bodies · No raw IPs

This describes evidence retained, displayed and exported by Security Observatory.

Review Architecture & Security →

Alongside Salesforce Security Center

Salesforce Security Center provides native security posture monitoring and security management for Salesforce orgs. Security Observatory is built around a different job: recording the applications, integrations and access that can reach your org, giving them accountable review context and keeping the evidence behind each entry. It is designed to complement Salesforce's native security capabilities, not replace them.

Review the exposure behind the headline count

  • Who owns each integration, and when was it last reviewed?
  • Which applications can access the org?
  • Who still holds OAuth access?
  • Which inactive users retain exposure?
  • Which credentials and external endpoints exist?
  • Where are selected powerful permissions assigned?
  • Which licences are being consumed?
  • Which evidence sources were incomplete or unavailable?
  • What evidence supports each conclusion?

Missing evidence must never become a clean result.

Conclusions retain their source and evidence context. When evidence is unavailable, it remains unavailable and must not silently become zero.

Why Security Observatory?

It gives supported applications and integrations durable accountability, connects OAuth evidence to user and application context, and brings credential, endpoint and public-surface evidence into the same review.

Each conclusion stays traceable to retained evidence and bounded by what the source could establish.

What a Security Observatory scan also reviews

Supporting breadth remains evidence-bounded and secondary to the governed application and integration record.

Configuration and application signals

Health Check configuration evidence, Connected Applications, certificates and sensitive administrative changes. Deeper Health Check and Tooling evidence requires subscriber self-callout setup.

Identity and privileged access

User posture, login and failed-login evidence, sessions, API-enabled access and selected powerful or data-exposure permissions.

Licence evidence

Licence capacity and bounded assignment evidence with explicit capture and completeness limits.

Continue the Security Observatory review

Explore the bounded V1 scope, or request access when it becomes available.

Email: info@fortmilo.co.uk